App Attest
Apple App Attest for the FundlyHub iOS app. A request carrying a valid assertion may skip reCAPTCHA on POST /payments/create-intent and POST /donations, guest or signed in. See the Native Clients guide for the byte-level protocol.
Issue an App Attest challenge
A random, single-use challenge for the iOS app, valid for
expires_in_seconds (300). Fetch one before attesting a key and one
before every donation request that carries an App Attest assertion.
Public (guests call it). Rate limited to 30 a minute per address.
Answers 503 with code: APP_ATTEST_DISABLED while App Attest is not
configured on the server.
Responses
A fresh challenge (Cache-Control: no-store).
Register an App Attest key
Register a device key with its attestation. The server verifies the
certificate chain to Apple's App Attestation Root CA, that the
attestation was made for challenge
(clientDataHash = SHA256(UTF-8 bytes of challenge)), the App ID, the
environment, a zero counter and that key_id is the key's hash, then
stores the public key. Attest once per key; attesting a key that is
already registered changes nothing.
Public (guests call it). Rate limited to 10 a minute per address.
Request Body
Responses
Key verified and registered.